Oval Definition:oval:org.mitre.oval:def:7990
Revision Date:2014-06-23Version:18
Title:DSA-1751 xulrunner -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Martijn Wargers, Jesse Ruderman and Josh Soref discovered crashes in the layout engine, which might allow the execution of arbitrary code. Jesse Ruderman discovered crashes in the layout engine, which might allow the execution of arbitrary code. Gary Kwong, and Timothee Groleau discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. Gary Kwong discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. It was discovered that incorrect memory management in the DOM element handling may lead to the execution of arbitrary code. Georgi Guninski discovered a violation of the same-origin policy through RDFXMLDataSource and cross-domain redirects. As indicated in the Etch release notes, security support for the Mozilla products in the oldstable distribution needed to be stopped before the end of the regular Etch security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a still supported browser.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-0771
CVE-2009-0772
CVE-2009-0773
CVE-2009-0774
CVE-2009-0775
CVE-2009-0776
DSA-1751
Platform(s):Debian GNU/Linux 5.0
Product(s):xulrunner
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND libmozillainterfaces-java is earlier than 1.9.0.7-0lenny1
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • libmozjs-dev is earlier than 1.9.0.7-0lenny1
  • OR spidermonkey-bin is earlier than 1.9.0.7-0lenny1
  • OR xulrunner-1.9-gnome-support is earlier than 1.9.0.7-0lenny1
  • OR xulrunner-1.9 is earlier than 1.9.0.7-0lenny1
  • OR libmozjs1d-dbg is earlier than 1.9.0.7-0lenny1
  • OR libmozjs1d is earlier than 1.9.0.7-0lenny1
  • OR python-xpcom is earlier than 1.9.0.7-0lenny1
  • OR xulrunner-1.9-dbg is earlier than 1.9.0.7-0lenny1
  • OR xulrunner-dev is earlier than 1.9.0.7-0lenny1
  • BACK